Draft for legal review. This document is a working draft and has not been reviewed by counsel. Bracketed placeholders (for example [Legal Entity Name], [Contact Email], [Effective Date], [Governing Jurisdiction]) must be completed and the full text approved by your attorney before publication or reliance.

Data Processing Addendum

Data Processing Addendum

This Data Processing Addendum (“DPA”) forms part of the agreement between [Legal Entity Name] (“Road,” the “Processor”) and the nonprofit customer (the “Controller”) for use of the Road platform (the “Service”). It reflects the requirements of Article 28 of the EU General Data Protection Regulation (GDPR) and equivalent obligations under the UK GDPR and the CCPA/CPRA.

Last updated: [Effective Date]


1. Roles of the parties#

For personal data contained in Customer Data, the Controller (the nonprofit) determines the purposes and means of processing, and Road acts as Processor, processing personal data only on the Controller’s documented instructions. The Controller’s donors and other contacts are the data subjects. Under the CCPA, Road is a “service provider” and will not sell or share personal information or use it outside the direct business relationship.

Where Road determines the means and purposes of processing limited account and usage data about the Controller’s own users, Road acts as an independent controller for that data; that processing is described in the Privacy Policy.

2. Subject matter, nature, and duration#

  • Subject matter: Road’s provision of the donor-management Service.
  • Nature and purpose: Hosting, storing, organizing, transmitting, and otherwise processing personal data to provide the Service and its features (including integrations and AI-assisted drafting), on the Controller’s instructions.
  • Duration: For the term of the agreement, plus the limited period needed to return or delete data as set out below.
  • Categories of data subjects: The Controller’s donors, prospective donors, household members, volunteers, organizational contacts, and the Controller’s own users.
  • Categories of personal data: Identification and contact details (name, address, email, phone), donation and pledge history, recurring-giving schedules, communication and activity records, tags and notes, and any other data the Controller chooses to store.
  • Special categories: The Service is not designed for special-category data. The Controller should not store such data except where it has a lawful basis and has configured the Service accordingly.

3. Processing on documented instructions (Art. 28(3)(a))#

Road will process personal data only on the Controller’s documented instructions, including with respect to international transfers, unless required to do otherwise by applicable law — in which case Road will inform the Controller before processing, unless legally prohibited. The agreement, this DPA, and the Controller’s configuration and use of the Service constitute the Controller’s complete instructions. Road will inform the Controller if, in its opinion, an instruction infringes applicable data-protection law.


4. Confidentiality (Art. 28(3)(b))#

Road ensures that persons authorized to process personal data are bound by confidentiality and are subject to appropriate training, and that access is limited to those who need it to provide the Service.


5. Security measures (Art. 28(3)(c) & Art. 32)#

Taking into account the state of the art and the risks of processing, Road maintains appropriate technical and organizational measures, including:

  • Tenant isolation enforced in PostgreSQL via Row-Level Security, so each Controller’s data is segregated at the database layer.
  • Encryption in transit (TLS) and encryption at rest for integration credentials and access tokens; passwords stored only as salted hashes.
  • Role-based access control within workspaces and least-privilege internal access.
  • Append-only audit logging of record mutations with actor attribution.
  • Logging, monitoring, and backup processes supporting availability and resilience.

6. Sub-processors (Art. 28(2) & 28(4))#

The Controller provides general authorization for Road to engage the sub-processors listed below, each bound by data-protection terms no less protective than this DPA. Road remains responsible for its sub-processors’ performance. Road will give the Controller reasonable prior notice of any intended addition or replacement of a sub-processor and an opportunity to object on reasonable data-protection grounds.

Sub-processorPurposeData processed
Hosting / managed Postgres providerApplication hosting and the primary Postgres database that stores all workspace data.All account and donor records processed in the platform.
ResendTransactional and outbound email delivery (verification, acknowledgments, notifications).Recipient email addresses, names, and message content.
TwilioOutbound and inbound SMS messaging and delivery status callbacks.Recipient phone numbers and message content.
VirtuousDonor-platform integration — bidirectional sync of contacts, donations, pledges, and recurring schedules.Donor contact records, donation and pledge data (only for workspaces that enable the integration).
QuickBooks Online (Intuit)Accounting integration — one-way push of customers, classes, sales receipts, refund receipts, and invoices.Donor names, donation amounts, and related financial records (only for workspaces that enable the integration).
Fundraise UpDonation-platform integration — ingest of online donations and donor records.Donor contact records and donation data (only for workspaces that enable the integration).
AI / LLM providerPowers Road AI Agent. Configurable per deployment (a local model by default; optionally an OpenAI-compatible hosted provider).Only the data included in a given prompt — e.g. a contact record or message the assistant is asked to act on. Not used to train third-party models when a hosted provider is configured with that setting.
Integration sub-processors receive personal data only for workspaces that enable the relevant integration. The AI sub-processor can be a self-hosted local model so that prompt content does not leave the Controller’s infrastructure; where a hosted provider is configured, only the data included in a given prompt is processed.

7. Assistance with data subject requests (Art. 28(3)(e))#

Taking into account the nature of the processing, Road will assist the Controller by appropriate technical and organizational measures, insofar as possible, to respond to data subject requests to exercise their rights (access, rectification, erasure, restriction, portability, and objection). The Service provides self-service access, export, and deletion tools the Controller can use directly. If Road receives a request from a data subject relating to a Controller’s data, Road will, where permitted, redirect the request to the Controller rather than respond directly.


8. Assistance with compliance obligations (Art. 28(3)(f))#

Road will assist the Controller, taking into account the nature of processing and the information available to Road, in ensuring compliance with its obligations regarding security, breach notification, data protection impact assessments, and prior consultation with supervisory authorities under Articles 32–36 of the GDPR.


9. Personal data breach notification#

Road will notify the Controller without undue delay, and in any event within [Notification Window — e.g. 72 hours] of becoming aware of a personal data breach affecting the Controller’s personal data. The notification will, to the extent known, describe the nature of the breach, the categories and approximate number of data subjects and records affected, likely consequences, and the measures taken or proposed to address it. The Controller is responsible for notifying supervisory authorities and affected data subjects where required.


10. Return and deletion on termination (Art. 28(3)(g))#

On termination of the Service, and at the Controller’s choice, Road will delete or return all personal data and delete existing copies, unless retention is required by applicable law. Records deleted within the Service are soft-deleted and excluded from use, then purged from backups on a rolling schedule. Final deletion or export of a workspace will be completed within [Deletion Window — e.g. 30 days] of termination, subject to legal retention requirements.


11. Audits and information (Art. 28(3)(h))#

Road will make available to the Controller information reasonably necessary to demonstrate compliance with this DPA and will allow for and contribute to audits, including inspections, conducted by the Controller or an auditor it mandates, subject to reasonable confidentiality, scheduling, and security conditions. Road may satisfy audit requests by providing relevant documentation or third-party reports where available.


12. International transfers#

Where Road processes personal data subject to the GDPR or UK GDPR outside the EEA or UK, the parties will rely on an appropriate transfer mechanism, including the EU Standard Contractual Clauses and the UK International Data Transfer Addendum, which are incorporated by reference where applicable. [Confirm transfer mechanism and module with counsel].


13. CCPA / CPRA terms#

  1. Road is a “service provider” processing personal information on the Controller’s behalf for the business purpose of providing the Service.
  2. Road will not sell or share personal information, retain, use, or disclose it for any purpose other than performing the Service, or outside the direct business relationship, except as permitted by law.
  3. Road certifies that it understands and will comply with these restrictions.

14. Precedence and general terms#

This DPA is incorporated into and forms part of the Terms of Service. In the event of a conflict between this DPA and the Terms regarding the processing of personal data, this DPA controls. All other terms of the agreement remain in full force. Liability under this DPA is subject to the limitations of liability in the Terms.


15. Contact#

Data-protection inquiries can be directed to [Legal Entity Name] at [Data Protection Contact Email], [Mailing Address]. See also our Privacy Policy.

Execution

Where a signed counterpart is required, this DPA may be executed by the Controller and Road as part of the order form or as a standalone document. [Signature blocks to be added on execution].